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DETAILED ACTION 

1. This action is responsive to the communication filed on September 11, 
2008. Claims 1-21 are pending. At this time, claims 1-21 are still rejected. 

Response to Arguments 

2. Applicant's arguments filed September 11, 2008 under 35 USC § 103 
have been fully considered but they are not persuasive. However, upon an in-depth 
reviewed and further consideration of the claimed language and the specification, a new 
ground(s) of rejection is made further in view of Scheifler (US 6,282,652 B1 ). 

Applicant's arguments filed February 19, 2008, with respect to the 
rejection(s) of claim(s) 1-4, 6-8, 11-13, and 16-21 under 35 USC § 101 have been fully 
considered and they are partially persuasive. Claims 11-13 are still not persuasive. 

Referring to claim 11, although applicant has overcome the non-statutory 
rejection for claims 1 and 6, it is unclear to the examiner that claim 11 with the mean- 
plus-function is statutory. According to the specification the step of generating a service 
request requiring security function comes from client application (see specification, page 
3, lines 17-19), which is a software module. Furthermore, how one could honoring said 
service request. The entire specification merely describes this "honoring" process. As 
a reminder to the applicant, that a software unit or module or application is not 
patentable. 

Thus, claim 11 is non-statutory subject matter. Claims 12-13 are 
depended on claim 1 1 , therefore they are also non-statutory subject matter. 

Furthermore, applicant has argued that the allegation that "these claims 
have limitations that are similar" appears to create a new standard which is not 
supported in controlling law. Perhaps most significant is that claims 11-20 have 
standards of patentability which are different as a matter of law. For example, claims ii- 
15 employ "means-plus-function" limitations which must be examined under MPEP 
2181-2184. The Examiner has not done so. Thus, the rejection of claims 11-20 is 
respectfully traversed for failure of the Examiner to actually examine the claims. Again, 
it is as reminder to the applicant and/or applicant's representative that claim 11 is a 
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broader version of claim 6, in which examiner has thoroughly examined it. If a narrow 
claim has fully rejected, it is obvious that the broader claim has also completely been 
covered by the narrow claim. Therefore, the rejection for claims 11-15 is efficient and 
proper. 

The fact that Examiner may not have specifically responded to any 
particular arguments made by Applicant and Applicant's Representative, should not be 
construed as indicating Examiner's agreement therewith. 

For the above reasons, it is believed that the rejections under 35 USC 101 
should be sustained. Since examiner recognizes there are still some issues with 35 
USC 101 and brings in a new prior art, this office action is a non-final. 

Claim Rejections - 35 USC § 101 

3. 35 U.S.C. 101 reads as follows: 

Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or 
any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and 
requirements of this title. 

4. Claims 11-15 are rejected under 35 U.S.C. 101 because the claimed 
invention is directed to non-statutory subject matter. 

a. Referring to claim 11: 

(1) Claim 11 recites An apparatus comprising: a. means for 
generating a service request requiring security functions including a user terminal 
computer; b. means responsively coupled to said generating means for honoring said 
service request while providing said security functions including a computer other than 
said user terminal computer; and c. means responsively coupled to said honoring 
means for embedding a security facility within a communication class library which 
provides said security functions. It does not contain a concrete system and would be 
considered non-statutory. According to the specification the step of generating a 
service request requiring security function comes from client application (see 
specification, page 3, lines 17-19), which is a software module. Furthermore, from a 
technical point of view, how one could carry out the step/process of honoring said 
service request. The entire specification merely describes this "honoring" process. As 
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a reminder to the applicant, that a software unit or module or application is not 
patentable. It is clearly that the client application and server application are software 
programs that are being used as programs, wherein these intangible media such as 
software or other program incapable of being touched or perceived absent the tangible 
medium through which they are conveyed. Thus, claim 1 does not recite any structure, 
i.e., machine to carry out the functions of all the recited steps. Therefore, claim 11 
recites non-statutory subject matter. Claims 12-15 depend on claim 11, therefore they 
are rejected with the same rationale applied against claim 1 1 above. 

Claim Rejections - 35 USC §112 

5 The following is a quotation of the second paragraph of 35 U.S.C. 1 12: 

The specification shall conclude with one or more claims particularly pointing out and distinctly 
claiming the subject matter which the applicant regards as his invention. 

6. Claims 11-15 are rejected under 35 U.S.C. 112, second paragraph, as 
being indefinite for failing to particularly point out and distinctly claim the subject matter 
which applicant regards as the invention. 

Claim 11 recites an apparatus comprising: a. means for generating a 
service request requiring security functions including a user terminal computer; b. 
means responsively coupled to said generating means for honoring said service request 
while providing said security functions including a computer other than said user 
terminal computer; and c. means responsively coupled to said honoring means for 
embedding a security facility within a communication class library which provides said 
security functions. It is unclear to the examiner, from a technical point of view, how one 
could carry out the step/process of honoring said service request. The entire 
specification merely describes this "honoring" process. Appropriate correction is 
required. 

Claims 12-15 depend on claim 11, therefore they are rejected with the 
same rationale applied against claim 11 above. 

Claim Rejections - 35 USC § 103 
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7. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for 
all obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

8. Claims 1, 6, 8-20 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Chung et al (US 6,012,090), and further in view of Scheifler (US 
6,282,652 B1). 

a. Referring to claim 1: 

i. Chung teaches an apparatus comprising: 

(1) a client application which generates a service request 
(column 4, lines 21-25 of Chung); 

(2) a service application responsively coupled to said 
client application which responds to said service request (column 4, lines 25-29 of 
Chung); 

(3) a communication class library which regulates 
communication between said client application and said service application (see Figure 
1 of Chung); 

(4) a security facility embedded within said 
communication class library (column 5, lines 19-27; column 11, lines 22-28 of 
Chung); and 

(5) wherein said security facility is automatically activated 
by said service request (column 11, lines 22-31 of Chung). 

ii. Although Chung teaches an apparatus for improving the 
efficiency of service request activity requiring security function in which registration 
applets may be written in the Java language and embedded in the HTML code of 
corresponding portions, or pages, of the browser program (column 5, lines 24-26 of 
Chung), Chung is silent on the capability of using a communication class library which 
regulates communication between said client application and said service application. 
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On the other hand, Scheifler teaches this limitation in column 4, lines 60-64 of 
Scheifler. 

iii. It would have been obvious to a person having ordinary skill 
in the art at the time the invention was made to: 

(1) have modified the invention of Chung with the 
teaching of Scheifler for the server to designate a separate set of communication 
requirements for each method invoked on behalf of a client or another server (column 
4, lines 55-57 of Scheifler). 

iv. The ordinary skilled person would have been motivated to: 
(1) have modified the invention of Chung with the 

teaching of Scheifler to improvement over conventional systems by permitting a server 
to designate communication requirements on a per-method basis (column 4, lines 53- 
54 of Scheifler). 

b. Referring to claim 6: 

i. Chung teaches a method of handling a service request from 
a client application to a service application comprising: 

(1) embedding a security facility within a communication 
class library (column 5, lines 19-27; column 11, lines 22-28 of Chung); 

(2) generating a service request within said client 
application (column 4, lines 21-25 of Chung); 

(3) transferring said service request from said client 
application to said service application (see Figure 1 of Chung); 

(4) receiving said service request by said service 
application (see Figure 1 of Chung); 

(5) honoring said service request by said service 
application (column 4, lines 25-29 of Chung); and 

(6) automatically implementing security functions from 
said embedded security facility during said step which honors said service request 
(column 5, lines 19-27; column 11, lines 22-28; column 4, lines 25-29 of Chung). 
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ii. Although Chung teaches an apparatus for improving the 
efficiency of service request activity requiring security function in which registration 
applets may be written in the Java language and embedded in the HTML code of 
corresponding portions, or pages, of the browser program (column 5, lines 24-26 of 
Chung), Chung is silent on the capability of using a communication class library which 
regulates communication between said client application and said service application. 
On the other hand, Scheifler teaches this limitation in column 4, lines 60-64 of 
Scheifler. 

iii. It would have been obvious to a person having ordinary skill 
in the art at the time the invention was made to: 

(1) have modified the invention of Chung with the 
teaching of Scheifler for the server to designate a separate set of communication 
requirements for each method invoked on behalf of a client or another server (column 
4, lines 55-57 of Scheifler). 

iv. The ordinary skilled person would have been motivated to: 
(1) have modified the invention of Chung with the 

teaching of Scheifler to improvement over conventional systems by permitting a server 
to designate communication requirements on a per-method basis (column 4, lines 53- 
54 of Scheifler). 

c. Referring to claim 8: 

i. The combination of teaching between Chung and Scheifler 
teaches the claimed subject matter. Chung further teaches: 

(1) wherein said transferring step further comprises 
transferring said service request to said service application via a publically accessible 
digital data communication network (see Figure 1 of Chung). 

d. Referring to claim 9: 

i. The combination of teaching between Chung and Scheifler 
teaches the claimed subject matter. Chung further teaches: 

(1) further comprising a user terminal wherein said client 
application is located within said user terminal (see Figure 1 of Chung). 
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e. Referring to claim 10: 

i. The combination of teaching between Chung and Scheifler 
teaches the claimed subject matter. Chung further teaches: 

(1) further comprising a data base management system 
wherein said service application is located within said data base management system 
(see Figure 1 of Chung). 

f. Referring to claims 11-20: 

i. These claims have limitations that are similar to those of 
claims 6-10, thus they are rejected with the same rationale applied against claims 6, 8- 
10 above. 

9. Claims 2-5, 21 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Chung et al (US 6,012,090), in view of Scheifler (US 6,282,652), and further in 
view of Herman et al (US 6,341 ,353 B1 ). 

a. Referring to claims 2. 4: 

i. The combination of teaching between Chung and Scheifler 
teaches the claimed subject matter. Although they both teach the security services, 
they are silent on the capability of using encryption/decryption objects in their security 
services. On the other hand, Herman teaches this limitation in column 18, lines 45-47 
of Herman. 

iii. It would have been obvious to a person having ordinary skill 
in the art at the time the invention was made to: 

(1) have modified the modified-invention of Chung with 
the teaching of Herman so that data is not visible to any but an authorized user/owner, 
(column 18, lines 36-37 of Herman). 

iv. The ordinary skilled person would have been motivated to: 
(1) have modified the modified-invention of Chung with 

the teaching of Herman so that two parties who do not trust each other can each 
determine that the other entity is who it claims to be. This is accomplished with 
authenticating protocols that may employ encryption, hashing, digital signatures, etc 
(column 18, lines 41-44 of Herman). 
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b. Referring to claim 3: 

i. The combination of teaching between Chung, Scheifler, and 
Herman teaches the claimed subject matter. Scheifler further teaches: 

(1) wherein said security facility further comprises 
security support provider interface (column 11, line 60 through line 7 of Scheifler). 

c. Referring to claim 5: 

i. The combination of teaching between Chung, Scheifler, and 
Herman teaches the claimed subject matter. Herman further teaches: 

(1) further comprising a user terminal responsively 
coupled to a data base management system via a publically accessible digital data 
communication network and wherein said client application is located within said user 
terminal and said service application is located within said data base management 
system (see Figure 1 of Chung; Figure 1 of Herman). 

d. Referring to claim 21: 

i. This claim has limitations that are similar to those of claims 
1-5, thus it is rejected with the same rationale applied against claims 1-5 above. 
Allowable Subject Matter 

10. Claim 7 objected to as being dependent upon a rejected base claim, but 
would be allowable if rewritten in independent form including all of the limitations of the 
base claim and any intervening claims. 

Conclusion 

1 1 . The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure. 

Any inquiry concerning this communication or earlier 
communications from the examiner should be directed to Thanhnga (Tanya) Truong 
whose telephone number is 571-272-3858. 

If attempts to reach the examiner by telephone are unsuccessful, 
the examiner's supervisor, Kim Vu can be reached at 571-272-3859. The fax and 
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phone numbers for the organization where this application or proceeding is assigned is 
571-273-8300. 

Any inquiry of a general nature or relating to the status of this 
application or proceeding should be directed to the receptionist whose telephone 
number is 571-272-2100. 

/Thanhnga B. Truong/ 

Primary Examiner, Art Unit 2135 



TBT 

December 7, 2008 



